Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.307 exploits
GitHub PoC
KimJuhyeong95/cve-2025-24514
CVE-2025-24514HIGH11 jun 2025
ingress-nginx controller - configuration injection via unsanitized auth-url annotation
68RIESGO
abrir
GitHub PoC
CVE-2025-24071
CVE-2025-24071MEDIUM10 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC2
Detection for CVE-2025-24016 - Deserialization of Untrusted Data Vulnerability in the Wazuh software
CVE-2025-24016CRITICALbajo ataque10 jun 2025
Remote code execution in Wazuh server
100RIESGO
abrir
GitHub PoC6
Proof-of-concept to CVE-2025-49113
CVE-2025-49113CRITICALbajo ataque10 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC6
A PoC exploit for CVE-2017-9841 - PHPUnit Remote Code Execution(RCE)
CVE-2017-9841CRITICALbajo ataque10 jun 2025
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
GitHub PoC
Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)
CVE-2022-26134CRITICALbajo ataqueransomware09 jun 2025
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
GitHub PoC
Arshit01/CVE-2023-20198
CVE-2023-20198CRITICALbajo ataque09 jun 2025
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS
100RIESGO
abrir
GitHub PoC
alm6no5/CVE-2025-32756-POC
CVE-2025-32756CRITICALbajo ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC
CVE-2021-3156-Exploit-Demo
CVE-2021-3156HIGHbajo ataque09 jun 2025
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
GitHub PoC
PoC malware that uses exploit CVE-2021-36934 (improper ACLs on shadow copies) using a fileless red team method on Windows 10/11 with LOLBins, extracting SYSTEM and SAM hives for local NTLM hashes.
CVE-2021-36934HIGHbajo ataque09 jun 2025
Windows Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC2
This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.
CVE-2025-49619HIGH09 jun 2025
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks suc
61RIESGO
abrir
GitHub PoC1
CVE-2024-10914 is a critical command injection vulnerability affecting several legacy D-Link Network Attached Storage (NAS) devices.
CVE-2024-10914CRITICAL09 jun 2025
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
85RIESGO
abrir
GitHub PoC
CVE-2025-32756: NSE Scanning for RCE in vulnerable FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera nodes
CVE-2025-32756CRITICALbajo ataque09 jun 2025
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa
90RIESGO
abrir
GitHub PoC1
CVE-2025-29927 - Critical Security Vulnerability in Next.js
CVE-2025-29972CRITICAL09 jun 2025
Azure Storage Resource Provider Spoofing Vulnerability
48RIESGO
abrir
GitHub PoC3
Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability
CVE-2025-24071MEDIUM09 jun 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
CyberBibs/SOC274---Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400-
CVE-2024-3400CRITICALbajo ataqueransomware08 jun 2025
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
100RIESGO
abrir
GitHub PoC
CVE-2025-0282
CVE-2025-0282CRITICALbajo ataqueransomware08 jun 2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7
100RIESGO
abrir
GitHub PoC
CVE-2024-40453 - Squirrelly v9.0.0 RCE. Poc
CVE-2024-40453CRITICAL08 jun 2025
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the com
48RIESGO
abrir
GitHub PoC
CyberBibs/Event-ID-263-Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-
CVE-2024-24919HIGHbajo ataqueransomware08 jun 2025
Information disclosure
100RIESGO
abrir
GitHub PoC
CVE-2025-31161
CVE-2025-31161CRITICALbajo ataqueransomware07 jun 2025
CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unle
100RIESGO
abrir
GitHub PoC
CVE-2025-31131
CVE-2025-31131HIGH07 jun 2025
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir
GitHub PoC1
CVE-2017-5638 Exploit Rewritten In Python By haxerr9
CVE-2017-5638CRITICALbajo ataqueransomware07 jun 2025
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
CVE-2024-51482 ZoneMinder v1.37.* <= 1.37.64 poc
CVE-2024-51482CRITICAL07 jun 2025
Boolean-based SQL Injection in ZoneMinder v1.37.* <= 1.37.64
75RIESGO
abrir
GitHub PoC
🚨 Exploit CVE-2025-55182 to demonstrate RCE in React Server Functions, highlighting risks from insecure prototype references in Next.js applications.
CVE-2025-55182CRITICALbajo ataqueransomware06 jun 2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1
100RIESGO
abrir
GitHub PoC18
mbanyamer/CVE-2025-24076
CVE-2025-24076HIGH06 jun 2025
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC
This is a little Python script to detect the "EvilSun" vulnerability (CVE-2020-14871) on Solaris systems. The vulnerability is a buffer overflow in the Pluggable Authentication Module (PAM) `pam_unix_auth` when handling keyboard-interactive authentication in SSH.
CVE-2020-14871CRITICALbajo ataque06 jun 2025
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
GitHub PoC2
CVE-2025-49113 exploit
CVE-2025-49113CRITICALbajo ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC90
Proof of Concept demonstrating Remote Code Execution through insecure deserialization in Roundcube (CVE-2025-49113).
CVE-2025-49113CRITICALbajo ataque06 jun 2025
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the
100RIESGO
abrir
GitHub PoC
POC
CVE-2025-30208MEDIUM06 jun 2025
Vite bypasses server.fs.deny when using `?raw??`
70RIESGO
abrir
GitHub PoC1
Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.
CVE-2021-4034HIGHbajo ataque05 jun 2025
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool
100RIESGO
abrir
anteriorpágina 144 / 444siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.